GC Cybersecurity cofounder Tarique Mustafa used his May 1, 2026 session at MIT Technology Review's EmTech AI conference to argue that the cybersecurity stack needs to be rebuilt with AI at its core, not bolted on after the fact. The session, titled "Cyber-Insecurity in the AI Era," was presented by GC Cybersecurity itself. Mustafa's pitch: the legacy approach was already buckling before generative AI arrived, and the attack surface has only widened since.
"Cybersecurity was already under strain before AI entered the stack," Mustafa said. "Now, as AI expands the attack surface and adds new complexity, the limits of legacy approaches are becoming harder to ignore." The framing is pointed in a market where most security vendors are shipping AI features as add-ons to products designed a decade ago.
Mustafa is cofounder and CEO/CTO of two companies — GC Cybersecurity and its data-compliance spinout Chorology, Inc. — and brings over 20 years of technical leadership to the argument. At GC Cybersecurity he architected the core AI powering what the company calls its 4th and 5th generation fully autonomous data leak protection and exfiltration platform.
Key facts
- 01GC Cybersecurity cofounder Tarique Mustafa argued at EmTech AI on May 1, 2026 that security must be rebuilt with AI at its core.
- 02Mustafa runs two AI-powered security companies: GC Cybersecurity and its data-compliance spinout Chorology, Inc.
- 03He architected the core AI for GC Cybersecurity's 4th and 5th generation autonomous data leak protection platform.
- 04Mustafa has over 20 years of technical leadership across Symantec, MCI WorldCom, EDS, NexTier Networks and Nevis Networks.
- 05He holds multiple USPTO patents in data security, AI planning, and knowledge representation.
Before founding GC Cybersecurity and Chorology, Mustafa was the founding CEO/CTO of NexTier Networks, a Silicon Valley data leak prevention vendor. His earlier career runs through Symantec, DHL Airways IT, MCI WorldCom, EDS, Andes Networks, and Nevis Networks, where he served as Principal Architect on intrusion detection, event correlation, and SSL/IPSec products.
“Cybersecurity was already under strain before AI entered the stack. Now, as AI expands the attack surface and adds new complexity, the limits of legacy approaches are becoming harder to ignore.”— Jaeden Schafer
He holds multiple approved and pending USPTO patents across data security, software architecture, database technologies, and artificial intelligence, with published research spanning the same fields. His academic credentials include master's degrees in engineering and computer science from the University of Southern California, where he studied on a Rotary International Scholarship, and a bachelor's in mechanical engineering from NED University of Engineering & Technology.
The substantive claim — that AI changes the security problem in kind, not just degree — lines up with what defenders are already seeing. Phishing kits now generate fluent multilingual lures. Voice cloning has collapsed the cost of social engineering. And autonomous agents, once they can read internal documents and call APIs, give attackers a new class of target: the agent itself, with its credentials and tool access.
Mustafa's counter is that defense has to become equally autonomous. Data leak protection, data security posture management, and data classification — the disciplines GC Cybersecurity sells into — all involve continuously inferring what data is sensitive, where it lives, and who is touching it. Those are inference problems, and inference problems are what AI does well, provided it's the architectural foundation rather than a feature flag.
The harder question is whether enterprise buyers will rip and replace. Most large companies have spent the past decade buying Symantec-era DLP, Microsoft Purview, and a stack of SIEM and SOAR tools that already claim AI capabilities. Convincing a CISO that all of that needs to be reconsidered is a tall order, even when the underlying argument is correct, and Mustafa did not name a specific platform or product as the alternative in the session description.
The pitch lands in a week where the AI security beat has been busy on the offensive side as well — OpenAI matched Anthropic on UK cybersecurity benchmarks, and the Pentagon signed Nvidia, Microsoft, and AWS to put AI on classified networks. The defensive side has been quieter, and that asymmetry is exactly the point Mustafa is trying to make. If the next decade of security tooling really does need to be AI-native from the kernel up, the vendors who started there have a window — and the ones layering chatbots on top of 2015-era engines have a problem they cannot patch their way out of.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.




